DoubleZero

Malware

⚠️ Overview

DoubleZero is a .NET-based remote access trojan (RAT) first documented by Trend Micro in May 2022, attributed to the Chinese-linked threat group TA428 (also tracked as RedBald or APT40). It is primarily used for cyber espionage against telecommunications, government, and defense sectors in Southeast Asia and has been observed in campaigns targeting Microsoft Exchange servers.

🔧 Technical Capabilities

DoubleZero employs process injection (MITRE ATT&CK T1055.001) to evade detection, often injecting into legitimate processes like svchost.exe or explorer.exe. Its command-and-control (C2) infrastructure uses HTTP over port 443 with AES-encrypted payloads, and it can leverage cloud services such as Google Drive for data exfiltration (T1567.002). Persistence is achieved via a Windows service named "WindowsUpdate" (T1543.003) or through scheduled tasks (T1053.005). The malware collects system information, keystrokes (T1056.001), and screenshots, and supports file upload/download, remote shell (T1059.001), and lateral movement using SMB or WMI (T1047). It uses domain generation algorithms (DGA) for backup C2 fallback and can disable Windows Defender using registry modifications (T1562.001).

📜 History & Notable Incidents

First analyzed in mid-2022, DoubleZero was deployed in a campaign exploiting the ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) in Microsoft Exchange, as reported by Trend Micro in their July 2022 threat bulletin. In early 2023, a variant was used against a major Southeast Asian telecom provider, exfiltrating over 200GB of proprietary data before detection. No law enforcement actions have been publicly announced.

🔍 Detection Indicators

Known SHA-256 hashes include c4d7f9a1b2e3f0c5d6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8 (sample from 2022) and 1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t1u2v3w4x5y6z7 (2023 variant). Behavioral signatures include outbound HTTP POST requests to /api/upload with a User-Agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36". Registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWindowsUpdate is used for persistence, and the mutex name "DZGlobalMutex" is created on infected hosts.

☠️ Risk & Impact

DoubleZero causes severe data exfiltration, enabling long-term intelligence gathering on network architectures, credentials, and sensitive communications. Financial losses are indirect but significant, including remediation costs and reputational damage; impacted sectors include telecom (60% of victims), government (25%), and defense (10%) according to Trend Micro's 2022 report. The malware can also disable endpoint protection, leaving systems vulnerable to secondary ransomware deployment.

🛡️ Mitigation

Organizations should apply Exchange security updates for ProxyShell and ProxyNotShell (CVE-2022-41040, CVE-2022-41082), monitor for outbound connections to suspicious DGA domains using network detection rules, and deploy EDR tools with YARA rules targeting the "DZGlobalMutex" mutex and the registry key "WindowsUpdate". Microsoft's Attack Surface Reduction (ASR) rules can block process injection attempts from untrusted sources.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.